Nuance Communications, Inc
bd_82faba2aed5d0b31 · schema v1 · pii pii-v1
Full breach record for Nuance Communications, Inc →3 incidents on fileNuance Communications reported a cyberattack on May 28-29, 2023, exploiting a zero-day vulnerability in Progress Software's MOVEit Transfer application. The incident impacted approximately 7,993 Washington residents, exposing names and radiology study details. Nuance secured servers, engaged Microsoft and legal counsel, notified the FBI and HHS OCR, and began notifying individuals on September 18, 2023.
J jump to incidentP pin to compareR raw source
Incident timeline
May 28, 2023
Begins
May 31, 2023
Discovered
Sep 15, 2023
Filed
vs. sector median
3 wks faster
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitecl0pbd_40ea5b2a63ba1e582023-06-16 · +91dVerified by operator
Regulatory filings (9) · sorted by filing gap
- Maine State AGbd_2d18f75acad25ac92023-09-15Verified
- New Hampshire State AGbd_42ba23005cabceb82023-09-15Verified
- California State AGbd_829cc01dc8d0b7322023-09-15Verified
- HHS OCRbd_cd3e342a18e72ccb2023-09-15Verified
Show 5 more filings ↓Show fewer ↑up to 257d gap
- Montana State AGbd_f82949cd77b8e1ac2023-09-15Verified
- Delaware State AGbd_119ca48980839f9b2023-09-18 · +3dVerified
- Oregon State AGbd_61e841c1c65090342023-09-19 · +4dVerified
- Illinois State AGbd_59fd556cb57cb64f2023-01-01 · +257dVerified by operator
- Illinois State AGbd_6a436e30174844602023-01-01 · +257dVerified by operator
Filing propagation · 10 filings · 9 states
View merged incident ↗Pattern: first filing Jan 1 (IL), last Sep 19 (OR) — a 261-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.